Jump to content

Eufy privacy controversy response

Yesterday I sent an email to Eufy support expressing how unhappy I was with this privacy issue. I think the response is mid and the security team should be a third party. The response is an obvious copy and paste PR template:

 

Quote

Dear (my name was here)

 

Dear eufy Client,

Thank you for contacting us! Thanks for all your trust along the way!

We understand all your concerns and worries.

In fact, eufy products, services, and processes are in full compliance with General Data Protection Regulation (GDPR) standards, including ISO 27701/27001 and ETSI 303645 certifications.

We have signed up a safety investigation team for this "Eufy leaking your 'private' images" posted by Mr. Paul Moore. We provide the facts and truth for all eufy users and make this statement here,


https://community.security.eufy.com/t/eufy-security-statement-to-our-community/3541186

Your trust is the reason why eufy grows fast in the past, and thrives in the future! If you have any concerns or questions, you are more than welcome to contact us at any time!

Link to the sites post: https://community.security.eufy.com/t/eufy-security-statement-to-our-community/3541186

Link to comment
Share on other sites

Link to post
Share on other sites

18 minutes ago, Gaimz said:

I think the response is mid and the security team should be a third party. The response is an obvious copy and paste PR template:

Chinese company breaching privacy. Imagine my shock.

 

Jokes aside, yeah it will be a very poor privacy policy as Chinese companies are basically state owned. Most devices like this if you sniff the traffic will often ping servers based in China with encrypted data.

Most of the time they ignore local laws and just play dumb when caught out with some PR spin on how they respect local laws and promise to change but they never do.

CPU: Ryzen 5900x | GPU: RTX 3090 FE | MB: MSI X470 Gaming Pro Carbon | RAM: 32gb Ballistix | PSU: Corsair RM750 | Cooler: Sythe Fuma 2 | Case: Phanteks P600s | Storage: 2TB WD Black SN 750 & 1TB Sabrent Rocket | OS: Windows 11 Pro & Linux Mint

Link to comment
Share on other sites

Link to post
Share on other sites

What?  They leaked your images?  Little more context please.

"Do what makes the experience better" - in regards to PCs and Life itself.

 

Onyx AMD Ryzen 7 7800x3d / MSI 6900xt Gaming X Trio / Gigabyte B650 AORUS Pro AX / G. Skill Flare X5 6000CL36 32GB / Samsung 980 1TB x3 / Super Flower Leadex V Platinum Pro 850 / EK-AIO 360 Basic / Fractal Design North XL (black mesh) / AOC AGON 35" 3440x1440 100Hz / Mackie CR5BT / Corsair Virtuoso SE / Cherry MX Board 3.0 / Logitech G502

 

7800X3D - PBO -30 all cores, 4.90GHz all core, 5.05GHz single core, 18286 C23 multi, 1779 C23 single

 

Emma : i9 9900K @5.1Ghz - Gigabyte AORUS 1080Ti - Gigabyte AORUS Z370 Gaming 5 - G. Skill Ripjaws V 32GB 3200CL16 - 750 EVO 512GB + 2x 860 EVO 1TB (RAID0) - EVGA SuperNova 650 P2 - Thermaltake Water 3.0 Ultimate 360mm - Fractal Design Define R6 - TP-Link AC1900 PCIe Wifi

 

Raven: AMD Ryzen 5 5600x3d - ASRock B550M Pro4 - G. Skill Ripjaws V 16GB 3200Mhz - XFX Radeon RX6650XT - Samsung 980 1TB + Crucial MX500 1TB - TP-Link AC600 USB Wifi - Gigabyte GP-P450B PSU -  Cooler Master MasterBox Q300L -  Samsung 27" 1080p

 

Plex : AMD Ryzen 5 5600 - Gigabyte B550M AORUS Elite AX - G. Skill Ripjaws V 16GB 2400Mhz - MSI 1050Ti 4GB - Crucial P3 Plus 500GB + WD Red NAS 4TBx2 - TP-Link AC1200 PCIe Wifi - EVGA SuperNova 650 P2 - ASUS Prime AP201 - Spectre 24" 1080p

 

Steam Deck 512GB OLED

 

OnePlus: 

OnePlus 11 5G - 16GB RAM, 256GB NAND, Eternal Green

OnePlus Buds Pro 2 - Eternal Green

 

Other Tech:

- 2021 Volvo S60 Recharge T8 Polestar Engineered - 415hp/495tq 2.0L 4cyl. turbocharged, supercharged and electrified.

Lenovo 720S Touch 15.6" - i7 7700HQ, 16GB RAM 2400MHz, 512GB NVMe SSD, 1050Ti, 4K touchscreen

MSI GF62 15.6" - i7 7700HQ, 16GB RAM 2400 MHz, 256GB NVMe SSD + 1TB 7200rpm HDD, 1050Ti

- Ubiquiti Amplifi HD mesh wifi

 

Link to comment
Share on other sites

Link to post
Share on other sites

6 minutes ago, Dedayog said:

What?  They leaked your images?  Little more context please.

Not sure how far out of the loop you are, but Linus and Luke talked about it on WAN Show last week.

 

 

TL;DW: Eufy smart doorbells were uploading unencrypted photos to servers, even though Anker (the parent company) said they only recorded locally. It was also possible to remotely initiate an unencrypted live stream from these devices, which could be viewed with plain old VLC. LMG's dropping Anker as a sponsor because of this.

 

https://www.macrumors.com/2022/11/29/eufy-camera-cloud-uploads-no-user-consent/

 

I sold my soul for ProSupport.

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, Needfuldoer said:

Not sure how far out of the loop you are, but Linus and Luke talked about it on WAN Show last week.

 

 

TL;DW: Eufy smart doorbells were uploading unencrypted photos to servers, even though Anker (the parent company) said they only recorded locally. It was also possible to remotely initiate an unencrypted live stream from these devices, which could be viewed with plain old VLC. LMG's dropping Anker as a sponsor because if this.

 

https://www.macrumors.com/2022/11/29/eufy-camera-cloud-uploads-no-user-consent/

 

Way out of the loop.

 

I don't watch LAN.  If I had, I wouldn't have posted a thread here about if it was already covered.  Not sure why the OP posted this.

"Do what makes the experience better" - in regards to PCs and Life itself.

 

Onyx AMD Ryzen 7 7800x3d / MSI 6900xt Gaming X Trio / Gigabyte B650 AORUS Pro AX / G. Skill Flare X5 6000CL36 32GB / Samsung 980 1TB x3 / Super Flower Leadex V Platinum Pro 850 / EK-AIO 360 Basic / Fractal Design North XL (black mesh) / AOC AGON 35" 3440x1440 100Hz / Mackie CR5BT / Corsair Virtuoso SE / Cherry MX Board 3.0 / Logitech G502

 

7800X3D - PBO -30 all cores, 4.90GHz all core, 5.05GHz single core, 18286 C23 multi, 1779 C23 single

 

Emma : i9 9900K @5.1Ghz - Gigabyte AORUS 1080Ti - Gigabyte AORUS Z370 Gaming 5 - G. Skill Ripjaws V 32GB 3200CL16 - 750 EVO 512GB + 2x 860 EVO 1TB (RAID0) - EVGA SuperNova 650 P2 - Thermaltake Water 3.0 Ultimate 360mm - Fractal Design Define R6 - TP-Link AC1900 PCIe Wifi

 

Raven: AMD Ryzen 5 5600x3d - ASRock B550M Pro4 - G. Skill Ripjaws V 16GB 3200Mhz - XFX Radeon RX6650XT - Samsung 980 1TB + Crucial MX500 1TB - TP-Link AC600 USB Wifi - Gigabyte GP-P450B PSU -  Cooler Master MasterBox Q300L -  Samsung 27" 1080p

 

Plex : AMD Ryzen 5 5600 - Gigabyte B550M AORUS Elite AX - G. Skill Ripjaws V 16GB 2400Mhz - MSI 1050Ti 4GB - Crucial P3 Plus 500GB + WD Red NAS 4TBx2 - TP-Link AC1200 PCIe Wifi - EVGA SuperNova 650 P2 - ASUS Prime AP201 - Spectre 24" 1080p

 

Steam Deck 512GB OLED

 

OnePlus: 

OnePlus 11 5G - 16GB RAM, 256GB NAND, Eternal Green

OnePlus Buds Pro 2 - Eternal Green

 

Other Tech:

- 2021 Volvo S60 Recharge T8 Polestar Engineered - 415hp/495tq 2.0L 4cyl. turbocharged, supercharged and electrified.

Lenovo 720S Touch 15.6" - i7 7700HQ, 16GB RAM 2400MHz, 512GB NVMe SSD, 1050Ti, 4K touchscreen

MSI GF62 15.6" - i7 7700HQ, 16GB RAM 2400 MHz, 256GB NVMe SSD + 1TB 7200rpm HDD, 1050Ti

- Ubiquiti Amplifi HD mesh wifi

 

Link to comment
Share on other sites

Link to post
Share on other sites

5 minutes ago, Dedayog said:

Way out of the loop.

 

I don't watch LAN.  If I had, I wouldn't have posted a thread here about if it was already covered.  Not sure why the OP posted this.

The WAN show is missing a bit of context, Eufy has facial recognition software that runs on the camera themselves (some people online are falsely saying the uploads to the Eufy servers is for the facial recognition, this isn't true), BUT, they do this for the notifications since the camera themselves can't really do that without some support (unless you're self-hosting, I don't see how cameras and doorbells could send you SMS or email notifications by themselves).

 

With that said, the fact that the user can't delete those images, and that you're being fingerprinted and will be recognized by other Eufy devices is HIGHLY sketchy to say the least, and that's why I have a hard time believing they're GDPR compliant.

 

See Paul Moore's videos if you want the source of the findings ;

 

 

 

 

One of Paul Moore's Tweet about GDPR compliance ;

 

If you need help with your forum account, please use the Forum Support form !

Link to comment
Share on other sites

Link to post
Share on other sites

So what's the next steps here? Anyway Eufy can fix this or the trust is completely gone?

If so, what are other options for ppl who want/need a security system?

Link to comment
Share on other sites

Link to post
Share on other sites

The fact deleting the account didn't delete the push notification cache is not surprising or a gdpr violation. They have 30 days to delete functionally required content. The cloudfront links automatically expire and it is basically impossible to guess the notification link unless you own the camera have its serial number and account info and event timestamp and do that within the day or so the link is valid. If you want fast and reliable rich push notifications you would actually need to send the pictures and face matches so they can be displayed on the user's device the moment they get network access. 

 

If they did a pure local relay solution it could be super slow or unreliable in poor network conditions. The user also has to enable face matches and turn on rich notifications. If you don't then the images are not sent. CDNs cache data short term deleting your account won't magically erase all traces right away.

 

You trade security for convenience. You could disable all notifications block it from the WAN network the VLC playback thing would be all that remains and is a feature and it's only exposed if you expose it directly to the internet as it's meant for LAN rstp streaming to a nas. If you mess that up you probably exposing your entire LAN as well.

 

They are selling more powerful more local Homebases but it's a cost vs. features thing they are purely local storage that is how they offer no subscription cost but notifications that work well have to transit the cloud and cdn caching is a reliability feature you'd want otherwise if you lose network for even a moment remotely you'd miss notifications and preview images and face matches you configured would not show up or would show up much later.

Link to comment
Share on other sites

Link to post
Share on other sites

Did anyone catch this deal on Newegg's Daily Deals today? Lol

Newegg trying to offload these devices before they're outlawed in the US/EU.

image.png.e6b38db5386fc156680a69cbbcf61d3c.png

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×